omnirouter
ModelsPricingIntegrationsEcosystemBlogDocsUpdates

Privacy Policy

Effective date: October 1, 2026

omnirouter.li is an independent project operated by Natsu in Morocco. This Privacy Policy explains how omnirouter (“we”, “us”) handles personal information when you visit the website, create or use an account, use the API or dashboard chat, make a payment, or contact us.

Privacy questions and requests can be sent to contact@omnirouter.li.

1. Information we handle

Account information

When you register, we handle information such as your email address, password, full name, organisation name, Telegram username, analytics preference, and referral or attribution information associated with registration.

API requests and usage

We process the content and parameters you submit so that we can route the request and return a model response. We keep operational and billing records such as request identifiers, model and provider information, status, token or other usage counts, price and charge information, latency, streaming status, retries, request and response sizes, and limited diagnostic information.

The ordinary usage-record system is designed to store usage metadata rather than prompt and response bodies. However, request content necessarily passes through our routing infrastructure and the provider serving the request. Do not submit information you are not authorised to process or disclose.

Optional debug capture

An organisation can enable debug capture for troubleshooting. Debug capture can store request and response bodies separately from ordinary usage records. It is disabled by default. Its default retention setting is 24 hours and its configured maximum is 30 days. Expired debug payloads are scheduled for deletion, although removal from active systems may not immediately remove every backup copy.

Dashboard chat and uploads

Dashboard chat stores conversation content, including messages and system prompts. If you upload images or files, we may store those files and text extracted from them. Dashboard chat records are separate from ordinary API usage records and are not governed by the debug-capture retention setting.

You may request deletion of dashboard chat or account-related personal information by contacting us. We may retain information where reasonably necessary for billing, security, dispute resolution, legal compliance, or backup integrity.

Payments

Payment checkout is provided by an external payment service. We keep transaction records such as provider and payment identifiers, amount, currency, status, checkout reference, wallet transaction references, failure information, refund information, invoices, and associated payment metadata. We do not ask you to send card credentials, cryptocurrency private keys, seed phrases, or account passwords to support.

Support

If you contact us, we handle the information included in your message and any related account, request, or payment references needed to respond.

2. Browser storage and analytics

We use session and security cookies to support authentication and protect requests. The configured session-cookie lifetime is 14 days.

The public website uses a first-party visitor identifier stored in your browser under omnirouter.visitor and sends page-visit information to our own tracking endpoint. This identifier is intended to be opaque and is not intended to contain your name or email address.

We use PostHog for product analytics, to understand how the website and service are used and to improve them. Analytics are on by default.

  • In your browser, PostHog records page views, clicks and other interactions, approximate location derived from your IP address, browser and device information, referrer, and session recordings of how pages are used. PostHog stores its own identifier in your browser's cookies and local storage. When you are signed in, these events are linked to your account (user ID, email address and name) and organisation.
  • From our servers, we send events about account and product activity: sign-up, sign-in, checkout started, credit added or payment failed, API keys issued or revoked, and API and image-generation requests with their model, provider, status, error code, latency, token counts and charge.

Analytics never include the content of prompts, chat messages, model responses, uploaded files, or API key values. Text fields are masked in session recordings, and chat transcripts and newly issued keys are excluded from capture entirely. PostHog's ingestion endpoint is in the United States.

An organisation owner or administrator can turn analytics off for the whole organisation at any time in Settings, or at sign-up. That setting applies to every member of the organisation and does not necessarily reflect each member's individual preference. Turning it off stops future events; events already sent cannot be recalled. You can also clear PostHog's identifier and the first-party visitor identifier using your browser's site-data controls.

3. Why we use information

We use information to:

  • create and administer accounts and API access;
  • process requests and deliver model responses;
  • provide dashboard chat and file-processing features;
  • calculate usage, maintain prepaid balances, and record payments and refunds;
  • secure, maintain, troubleshoot, and improve the service;
  • respond to support and privacy requests;
  • measure and analyse website and product usage to improve the service, unless analytics are turned off for your organisation; and
  • comply with applicable law and resolve disputes.

Depending on the processing and applicable law, we rely on providing the requested service, consent, legitimate operational and security interests, or legal obligations. You can turn analytics off for future events through the organisation setting described in section 2.

4. Who receives information

Request content and necessary parameters are transmitted through our routing infrastructure to the external provider selected to serve the request. Routing and failover can change which provider receives a request. Model creators shown in the public catalog are not necessarily the same organisations that supply every routed request.

We also use service providers for functions such as hosting and infrastructure, payments, analytics, and support. These providers receive information only as needed for their functions or as otherwise disclosed to you. Provider practices can differ, and we do not promise that every external AI provider follows a universal zero-retention or no-training policy.

We may disclose information where required by applicable law or where reasonably necessary to investigate fraud, abuse, security incidents, or threats to rights and safety.

5. International processing

The service can process information outside Morocco because inference, infrastructure, payment, and analytics providers may operate in other countries. In particular, the configured PostHog analytics endpoint is in the United States. We seek to use appropriate contractual and operational safeguards where applicable, but the exact location and legal framework can differ by provider and request.

6. Retention

We retain information only while reasonably needed for the purposes described in this policy, including providing the service, maintaining billing and security records, resolving disputes, and meeting legal obligations.

Specific handling includes:

  • debug-capture payloads use the configured expiry described above;
  • dashboard conversations and uploads remain available until deleted or no longer reasonably needed;
  • account, usage, payment, refund, invoice, security, and support records may be kept while the account is active and afterwards where needed for the purposes above; and
  • backups can retain copies for a limited operational period after information is removed from active systems.

We do not claim immediate deletion from every backup. Where a retained backup is restored, deletion and restriction requirements should be reapplied as part of normal recovery procedures.

7. Your rights and choices

Subject to applicable law, you may request access to personal information about you, correction, deletion, restriction, objection, or a portable copy. You may also withdraw consent where processing is based on consent and complain to a competent data-protection authority.

There is currently no self-service account-deletion or data-export control. Send requests to contact@omnirouter.li. We may ask for information needed to verify your identity and authority over the relevant account. Some information may be retained where required or permitted for billing, security, legal compliance, fraud prevention, or dispute resolution.

If Moroccan data-protection law applies, information about rights and complaints is available from Morocco's National Commission for the Control of Personal Data Protection (CNDP).

8. Security

Customer API keys are shown in full only when created. The service stores a one-way hash and limited display prefix rather than the full issued customer key. Other internal credentials can require different protected storage because they must remain usable by the service.

No service is completely secure. Keep credentials confidential, restrict access to your account, and contact contact@omnirouter.li if you suspect unauthorised use.

9. Children

The service is intended for users who can lawfully enter into the agreement themselves or use it under the authority of an organisation or responsible adult. Do not create an account or submit children's personal information unless you have the legal authority and appropriate safeguards to do so.

10. Changes

We may update this policy as the service changes. The updated version will be posted on this page with a revised effective date. If a change materially affects how we use personal information, we will provide additional notice where reasonably practicable or legally required.

11. Contact

Operator: Natsu, operating the independent project omnirouter.li
Country: Morocco
Email: contact@omnirouter.li

omnirouter
ModelsPricingIntegrationsEcosystemBlogDocsUpdatesPrivacyTerms

© 2026 omnirouter. One API, every model.

Support:@Omnirouter_support·contact@omnirouter.li